Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2g99-c67p-56hm

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

XML Signature/Encryption Not Validated in Apache CXF

Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.

Ссылки

Пакеты

Наименование

org.apache.cxf:cxf

maven
Затронутые версииВерсия исправления

>= 2.4.0, < 2.4.8

2.4.8

Наименование

org.apache.cxf:cxf

maven
Затронутые версииВерсия исправления

>= 2.5.0, < 2.5.4

2.5.4

Наименование

org.apache.cxf:cxf

maven
Затронутые версииВерсия исправления

>= 2.6.0, < 2.6.1

2.6.1

EPSS

Процентиль: 88%
0.03752
Низкий

Связанные уязвимости

redhat
больше 13 лет назад

Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.

nvd
около 13 лет назад

Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.

EPSS

Процентиль: 88%
0.03752
Низкий